77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
KRITIS obligation: Which operators will be subject to the stricter regulation in 2026
IT Security & NIS-2

KRITIS obligation: Which operators will be subject to the stricter regulation in 2026

1 September 202613 min readBy Lena Vogt
CIVAC

In 2026, the KRITIS obligations will be bundled from BSIG, KRITIS-DachG and NIS-2. Those affected have two years for implementation. The thresholds, sectors and fines in an operational overview.

The obligations for operators of critical infrastructures (KRITIS) will expand significantly in 2026. Three sets of regulations intertwine: the BSI Act in the version of the NIS 2 Implementation Act, the KRITIS umbrella law (KRITIS-DachG) and the KRITIS regulation (KritisV). The BMI estimates that around 29,500 affected companies in Germany are affected, a multiple of the current 2,000 KRITIS operators.

This article explains the specific threshold values, the registration requirement with the Federal Office for Information Security (BSI), the evidence that is due every two years and the operational consequences for the information security officer. You can find a more in-depth regulatory classification of the NIS 2 implementation at civac.de/news/nis-2-umstellung-deutschland-2026.

Key Takeaways

  • In 2026, KRITIS obligations apply in parallel to three legal bases: BSIG (cybersecurity), KRITIS-DachG (physical security) and sectoral regulations.
  • Registration with the BSI is mandatory within four months of entry into force or after the threshold values ​​have been exceeded (§ 8b BSIG-new).
  • Obligation to provide evidence every two years of appropriate technical and organisational precautions; Fines of up to 20 million euros or 2 percent of group sales.

What KRITIS encompasses today: sectors and thresholds

The KRITIS Ordinance (KritisV) in its current version defines ten sectors: energy, water, nutrition, information technology and telecommunications, health, finance and insurance, transport and traffic, municipal waste disposal, state and administration as well as media and culture. With the KRITIS-DachG, additional sectors are being added, including space travel and the chemical industry.

Threshold values ​​are sector-specific and are based on the level of coverage. Examples from the KritisV: Electricity generation from 420 MW installed net nominal output, water supply from 500,000 people served, hospitals from 30,000 fully inpatient cases per year, data centres from 3.5 MW output.

The threshold values ​​are expected to be lowered in 2026. The draft bill of the KRITIS-DachG already provides for smaller levels of coverage, so that significantly more operators than before are subject to regulation.

NIS-2 distinguishes between essential entities and important entities. The classification depends on the sector, number of employees from 250 or 50, and annual turnover from 50 million or 10 million euros. These thresholds complement the KRITIS thresholds, but do not replace them.

Several threshold values ​​can apply in parallel. A power grid operator can simultaneously be a KRITIS operator according to KritisV (sectoral) and an essential facility according to NIS-2 (universal). The stricter duty prevails.

Obligation to register with the BSI

According to Section 8b BSIG-new (in the NIS 2 implementation version), KRITIS operators must register with the BSI within four months after the obligation comes into force or after the threshold values ​​are exceeded. Registration takes place via the BSI reporting portal with information about the operator, system and contact point.

The obligation to self-register is a significant tightening. Before NIS-2, the BSI had to identify and write to the operators. In the future, the responsibility lies with the operator; overlooking your own KRITIS feature is no excuse.

As part of registration, you will be named a contact point that can be reached at all times for security-related incidents. This contact point is not the same as the information security officer, but may be the same person.

The registration data is checked and updated every two years. Changes in the group of operators (sales, mergers, restructuring) must be reported immediately. The clock starts on awareness.

The CIVAC workspace maintains a master data set for KRITIS registrations with versioning, a reminder function for two-year updates and templates for the BSI reporting forms. The appointment certificate, signed, filed, verifiable.

Obligation to provide proof every two years

§ 8a BSIG-new obliges KRITIS operators to provide evidence of the status of the precautions taken to the BSI every two years. Proof is provided through an audit by an auditor recognised by the BSI, through an ISO/IEC 27001:2022 certificate with additional KRITIS requirements, or through sector-specific standards such as B3S.

Industry-specific safety standards (B3S) are recognised specifications for individual sectors, for example B3S Hospital, B3S Water, B3S Energy. They are not mandatory, but they make proof considerably easier because the BSI has recognised them as appropriate.

The scope of the test is broader than a pure ISO 27001 test. Not only the ISMS controls are tested, but also the specific resilience against failure-related threats to the critical function. A power network operator must prove that network management can continue to be carried out even in the event of an IT failure.

Deficiencies in evidence are subject to fines in accordance with Section 14 of the BSIG-new. Fines range up to 20 million euros or 2 percent of global group sales (whichever is higher), for essential facilities. Important institutions are threatened with a fine of up to 10 million euros or 1.4 percent.

The Information Security Officer is operationally responsible for the preparation and support of the evidence review. Audit-proof, documented, § 8a-firm.

Incident reporting requirement: 24 + 72 hours

Incidents with significant impact on critical function must be reported. The deadlines from NIS-2 (adopted in BSIG-new) are strict: 24 hours of early warning after knowledge, 72 hours of formal reporting, one month of final report.

The 24-hour early warning contains initial information: type of incident, suspected course of events, affected systems, suspected cause. It is deliberately kept low-threshold because there is rarely complete clarity at the time of the report.

The 72-hour report deepens the findings: extent of damage, affected data categories, countermeasures taken, impact on other operators. Several data breach interfaces are possible: at the same time, a GDPR report according to Art. 33 GDPR can be made to the state data protection authority, with its own 72-hour deadline.

The final report after one month documents the cause analysis, the effectiveness of the countermeasures, lessons learned and planned improvements. It is the basis for the assessment by the BSI and can be incorporated into subsequent fine proceedings.

Operational consequence: KRITIS operators need a prepared reporting path with clear escalation levels, templates for the three reporting documents and a named 24/7 contact point. The auditor calls, the evidence is ready.

Interfaces between BSIG, KRITIS-DachG and NIS-2

Three sets of rules will apply in parallel in 2026. The BSIG-new (NIS 2 Implementation Act) regulates the cybersecurity of critical systems. The KRITIS-DachG supplements physical security and resilience against non-cyber-related threats such as sabotage, natural events and pandemics. The KritisV defines sectoral thresholds.

Anyone who is obliged to comply with several regulatory areas should not duplicate the requirements, but rather bundle them in an integrated security management system. ISO/IEC 27001:2022 with the 93 controls forms the IT part, supplemented by business continuity requirements from ISO 22301 for physical resilience.

Supervision is multi-pronged: BSI for IT security, sectoral supervisory authorities (BaFin, Federal Network Agency, Federal Railway Authority) for operational security, state interior ministries for disaster control, Federal Criminal Police Office for sabotage. Central compliance control in the company is therefore more important than before.

Industry associations (BDEW Energie, DWA Wasser, DKG Hospital, BDI Industrie) offer sector-specific interpretation aids. These are not legally binding, but influence administrative practice and the acceptance of verification methods.

In the CIVAC workspace, a mapping maps the obligations from all three sets of rules to the internal controls. A measure typically covers several regulatory requirements. Others run compliance like a filing cabinet. We run it like software.

Supply chain obligations and third party risk

NIS-2 and KRITIS-DachG extend the scope of obligations to the supply chain. KRITIS operators must systematically assess and contractually secure risks from service providers, software suppliers and cloud providers. A mere standard clause in the contract is not enough.

Specifically, Section 8a Paragraph 3 BSIG-neu requires that security requirements also be enforced against third parties. Audit rights, sub-service provider clauses, reporting obligations in the event of incidents, and termination rights in the event of security deficiencies belong in the standard contract architecture.

Software supply chains are becoming particularly important. CISA's SBOM initiative and parallel efforts at the EU level require transparency about the components of commercial software. KRITIS operators should request a software bill of materials for critical software.

Cloud providers are the most common third party for critical functions. Here, the EU AI regulation in combination with DORA tightens the requirements for financial service providers. Sovereign cloud solutions with EU data residency and EU ownership structure are already the procurement standard in many sectors.

The CIVAC workspace offers a supplier auditor module with templates for security due diligence, annual risk assessment and re-audit reminders. Licence the workspace for your internal representatives or have our representatives order it.

Management liability according to Section 38 BSIG-new

A central breach of the NIS 2 implementation compared to the old law is the personal liability of management. § 38 BSIG-new obliges managing directors and board members personally to monitor and approve the implementation of security requirements.

Violations of this obligation not only lead to company fines, but can trigger personal liability according to § 43 GmbHG or § 93 AktG. In the event of a dispute, the burden of proof lies with the management: Anyone who has not documented that they exercised appropriate care is liable.

Specifically, this means: regular risk reports from the ISB to the management, documented decisions on measures and residual risks, approval of essential security budgets by the management body. These processes must be on record, not just discussed informally.

D&O insurance should be checked for NIS 2-specific exclusions. Standard policies exclude intentional breaches of duty but cover negligence. The line between gross negligence and intent is difficult in the cyber context; an update to the 2026 policy is advisable.

Compulsory training for management is new. According to Section 38 Paragraph 3 BSIG-new, members of the management body must complete cybersecurity training. An annual refresh with documented evidence is the usual market standard.

Transition periods and preparation path

The NIS 2 Implementation Act is expected to come into force at the beginning of 2026, with staggered transition periods. Registration with the BSI: four months from entry into force or from the threshold values ​​being exceeded. Full implementation of the security requirements: 24 months from entry into force.

The first proof according to § 8a BSIG-new is due 24 months after entry into force, and then every two years. Anyone who does not yet have a plan in 2026 will lose half of the available time window for inventory and conception.

A realistic preparation path is divided into four phases: inventory (two to three months), conception (three months), implementation (twelve months), evidence preparation and audit (three to six months). Anyone who wants to approach everything in parallel will fail due to a lack of resources.

Quick wins for the first 90 days: identification of the KRITIS property with threshold check, naming of ISB and reporting contact, risk inventory of the most important systems, gap check against ISO/IEC 27001:2022 Annex A. This preparatory work costs little and enables valid effort estimates.

External support in the conception phase is common more economical than exclusively internal development. The external ISB can act temporarily or permanently, with an appointment certificate and a clear reporting line to the management.

CIVAC: KRITIS obligations in one platform

The KRITIS obligations 2026 require an integrated view: threshold check, registration, risk inventory, action plan, training, incident reporting path, evidence audit. Fragmented tools (Excel for inventory, Word for measures, separate reporting tool) break down interfaces and significantly extend preparation time.

CIVAC is a compliance platform and officer-as-a-service. The workspace bundles KRITIS-specific templates, NIS 2-compliant reporting paths with 24- and 72-hour clocks, ISO/IEC 27001:2022 mapping across 93 controls and a supplier auditor module for the third-party requirement from Section 8a BSIG-neu.

Model one: You licence the workspace for your internal representatives. Your ISB manages KRITIS compliance itself, supported by 490 ready-to-use audit templates, master data management and automatic reminders for the two-year verification check.

Model two: You have our representatives appointed. An experienced external information security officer takes operational responsibility, with an appointment certificate, reporting line to your management and an SLA of two business days instead of the industry standard two to six weeks.

Both models use the same workspace and the same audit trail. KRITIS operators often initially switch from external ISB to the hybrid model once internal capacity is built up. The platform remains constant.

Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. We typically start with a threshold check and a 30-day roadmap for the first steps.

FAQ

How do I know whether my company falls under the KRITIS obligation?

Check two axes: sector (energy, water, health, IT, finance, transport and others) and threshold according to KritisV or NIS-2. Threshold values ​​relate to the level of supply or number of employees and sales. In borderline cases, a written threshold analysis is recommended, which demonstrates a duty of care in the event of an audit.

What deadlines apply according to the NIS 2 Implementation Act?

Registration with the BSI within four months of entry into force or exceeding the thresholds. Full implementation of security requirements 24 months after entry into force. First proof after 24 months, then every two years. Incident reporting 24 hours early warning, 72 hours follow-up notification, one month final report.

What happens if I overlook the CRITICISM property?

Since NIS-2, the responsibility for collection lies with the operator. Overlooking something is no excuse. Fines according to Section 14 BSIG-new range up to 20 million euros or 2 percent of global group sales. In addition, there is personal liability of the management in accordance with Section 38 BSIG-new and reputational consequences in the event of official complaints.

Do I need an external or internal ISB?

Both are permitted by law. External information security officers make sense when there is a lack of internal capacity, quick needs or smaller organisations. Internal ISB is worthwhile with around 500 employees and mature security processes. Mixed models with external ISB being set up and internal takeover after 18 to 24 months are common.

What is the difference between KRITIS operator and essential facility according to NIS-2?

You become a KRITIS operator by exceeding sector-specific thresholds from the KritisV (e.g. level of coverage). You become an essential or important facility based on NIS-2 criteria (sector plus number of employees from 250 or 50 plus turnover). Both categorizations can operate in parallel; the stricter duty prevails.

Is an ISO/IEC 27001:2022 certification sufficient as KRITIS proof?

It is a strong foundation, but does not cover all KRITIS-specific requirements. Supplements such as B3S standards for the respective sector or additional proof of resilience are regularly required. The BSI accepts ISO 27001 plus B3S or equivalent specifications as the standard method for proof in accordance with Section 8a BSIG-new.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles